VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5712 CVEsRSS

CVE-2024-29033High· 7.5
2y ago

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

▾ Twilightoauthenticator · oauthenticatorEPSS 0.59%via OSV
CVE-2024-21503Medium· 5.3
2y ago

Black vulnerable to Regular Expression Denial of Service (ReDoS)

Black vulnerable to Regular Expression Denial of Service (ReDoS)

▾ Sunlitblack · blackEPSS 0.98%via OSV
CVE-2024-1753High· 8.6PoC
2y ago

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…

▾ MidnightRed Hat · buildahEPSS 0.49%via NVD
CVE-2024-21661High· 7.5
2y ago

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment

▾ Twilightargoproj · github.com/argoproj/argo-cdEPSS 1.2%via OSV
CVE-2024-28248High· 7.2
2y ago

Intermittent HTTP policy bypass

Intermittent HTTP policy bypass

▾ Twilightcilium · github.com/cilium/ciliumEPSS 0.62%via OSV
CVE-2024-21652Medium· 5.4
2y ago

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

Bypassing Rate Limit and Brute Force Protection Using Cache Overflow

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.75%via OSV
CVE-2024-28865High· 7.5
2y ago

Denial of service via regular expression

Denial of service via regular expression

▾ Twilightwiki · wikiEPSS 0.61%via OSV
CVE-2024-29156Medium· 6.5
2y ago

Information leakage in YAQL

Information leakage in YAQL

▾ Sunlityaql · yaqlEPSS 0.75%via OSV
CVE-2023-41334High· 8.4
2y ago

RCE in TranformGraph().to_dot_graph function

RCE in TranformGraph().to_dot_graph function

▾ Twilightastropy · astropyEPSS 1.1%via OSV
CVE-2024-22513LowPoC
2y ago

Improper Privilege Management in djangorestframework-simplejwt

Improper Privilege Management in djangorestframework-simplejwt

▾ Twilightdjangorestframework-simplejwt · djangorestframework-simplejwtEPSS 0.80%via OSV
CVE-2024-27351Medium· 5.3
2y ago

Regular expression denial-of-service in Django

Regular expression denial-of-service in Django

▾ Sunlitdjango · djangoEPSS 1.9%via OSV
CVE-2024-28854High· 7.5
2y ago

tls-listener affected by the slow loris vulnerability with default configuration

tls-listener affected by the slow loris vulnerability with default configuration

▾ Twilighttls-listener · tls-listenerEPSS 0.96%via OSV
CVE-2024-28175Critical· 9.0
2y ago

Cross-site scripting on application summary component

Cross-site scripting on application summary component

▾ Midnightargoproj · github.com/argoproj/argo-cdEPSS 0.65%via OSV
CVE-2023-50726Medium· 6.4
2y ago

Users with `create` but not `override` privileges can perform local sync

Users with `create` but not `override` privileges can perform local sync

▾ Sunlitargoproj · github.com/argoproj/argo-cdEPSS 0.53%via OSV
CVE-2024-24770Medium· 5.3
2y ago

vantage6 vulnerable to a username timing attack on recover password/MFA token

vantage6 vulnerable to a username timing attack on recover password/MFA token

▾ Sunlitvantage6 · vantage6EPSS 0.40%via OSV
CVE-2024-23823Medium· 4.2
2y ago

vantage6's CORS settings overly permissive

vantage6's CORS settings overly permissive

▾ Sunlitvantage6 · vantage6EPSS 0.31%via OSV
CVE-2024-28423Critical· 9.8
2y ago

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vuln…

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

▾ Midnightairflow-diagrams · airflow-diagramsEPSS 0.78%via OSV
CVE-2024-1410Low· 3.7
2y ago

quiche vulnerable to unbounded storage of information related to connection ID retirement

quiche vulnerable to unbounded storage of information related to connection ID retirement

▾ Sunlitquiche · quicheEPSS 0.66%via OSV
CVE-2024-1765Medium· 5.9
2y ago

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

▾ Sunlitquiche · quicheEPSS 1.2%via OSV
CVE-2024-27097Medium· 4.3
2y ago

Potential log injection in reset user endpoint in CKAN

Potential log injection in reset user endpoint in CKAN

▾ Sunlitckan · ckanEPSS 0.44%via OSV
CVE-2024-26164High· 8.8
2y ago

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server

▾ Twilightmssql-django · mssql-djangoEPSS 2.1%via OSV
CVE-2024-52288Medium· 5.1
2y ago

LibOSDP RMAC revert to the beginning of the session

LibOSDP RMAC revert to the beginning of the session

▾ Sunlitlibosdp · libosdpEPSS 0.13%via OSV
CVE-2024-2319Medium· 5.4
2y ago

Django MarkdownX Cross-Site Scripting (XSS) vulnerability

Django MarkdownX Cross-Site Scripting (XSS) vulnerability

▾ Sunlitdjango-markdownx · django-markdownxEPSS 0.39%via OSV
CVE-2024-52296Medium· 6.5
2y ago

LibOSDP vulnerable to a null pointer deref in osdp_reply_name

LibOSDP vulnerable to a null pointer deref in osdp_reply_name

▾ Sunlitlibosdp · libosdpEPSS 0.35%via OSV
CVE-2024-28184High· 7.4
2y ago

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

▾ Twilightweasyprint · weasyprintEPSS 0.74%via OSV
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2024-0917Critical· 9.8
2y ago

PaddlePaddle vulnerable to remote code execution

PaddlePaddle vulnerable to remote code execution

▾ Midnightpaddlepaddle · paddlepaddleEPSS 1.7%via OSV
CVE-2024-0818Critical· 9.1
2y ago

PaddlePaddle Path Traversal vulnerability

PaddlePaddle Path Traversal vulnerability

▾ Midnightpaddlepaddle · paddlepaddleEPSS 1.1%via OSV
CVE-2024-0815High· 8.8
2y ago

PaddlePaddle command injection in paddle.utils.download._wget_download

PaddlePaddle command injection in paddle.utils.download._wget_download

▾ Twilightpaddlepaddle · paddlepaddleEPSS 1.1%via OSV
CVE-2024-0817High· 7.8
2y ago

PaddlePaddle command injection vulnerability

PaddlePaddle command injection vulnerability

▾ Twilightpaddlepaddle · paddlepaddleEPSS 1.2%via OSV
CVEs tagged “osv” — page 135 · VulnSea